

Pre-booking open · NyxShield and NyxAssure→Find what's exploitable.Prove it's fixed.
NyxShield finds what an attacker would and retests every fix. NyxAssure turns that evidence into SOC 2 and ISO 27001 readiness.NyxShield pentesting and NyxAssure SOC 2 / ISO 27001 readiness.
Your pentester is verifying a finding
Teams that ship with NyxSentinel behind them
Find what an attacker would. Prove it's fixed.
Human-led penetration tests for web apps and APIs. Findings are reproduced before release, tracked in your console, and closed only after our retest analyst confirms the fix.
- coversWeb apps, REST and GraphQL APIs, cloud-hosted assets
- methodOWASP Testing Guide and NIST SP 800-115, manual testing on top of automated scans
- you getA live findings console, CVSS scoring, retests and an audit-ready report
Retest analystverifying fixesSOC 2 and ISO 27001 readiness, built on evidence you already have.
Connect the tools you run. NyxAssure maps what they prove to your controls and to the criteria an auditor checks, drafts your policies and keeps a risk register current.
- connectsAWS, GitHub, Google Workspace, Microsoft, Jira, CrowdStrike, Apple
- tracksEvidence facts, controls, framework criteria, a 5×5 risk register
- pairs withNyxShield, whose reports and retests already count as evidence
Compliance leadsigning offPricing goes public soon. You can hold your place now.
Join the list and we'll send a quote for your exact scope before we open to everyone. These are the people you'll work with.
pentester
retest analyst
compliance lead
your engineerThe most competitive price on the market, for industry-standard work.
- nyxshield
- OWASP Testing Guide and NIST SP 800-115, with manual testing on top of automated scans
- deliverables
- Executive summary, technical report with CVSS scores, remediation roadmap, retests
- nyxassure
- Evidence mapped to SOC 2 and ISO 27001 criteria, AI-drafted policies with e-signature, a 5×5 risk register
- commitments
- NyxShield: CVSS ≥ 8.0 reported immediately, final report within 5 business days. NyxAssure: a readiness score against every criterion in scope.
Before you pre-book.
Anything else goes to business@nyxsentinel.com, and a person answers.
Testing is non-destructive by contract: no denial-of-service, no exploits that risk data loss or downtime, and no changes to your data. If anything looks unstable we stop, and your emergency stop phrase halts all active testing at any point.
Scanners find known patterns. They don't notice that your refund endpoint accepts negative quantities, or that changing one ID returns another customer's data. Our testers use tools for coverage, then spend their time on authorization, business logic and chained attacks. Every finding is reproduced before you see it, and fixes are retested.
Anything at CVSS 8.0 or higher is released to your console as soon as it's confirmed, and you're alerted at the same moment if you turned instant alerts on during onboarding.
If a customer or investor is asking for a pentest, start with NyxShield. If you're heading into SOC 2 or ISO 27001, NyxAssure handles evidence, controls, risks and policies, and your NyxShield results feed into it.
No. NyxAssure gets you ready: controls, evidence, risks and policies in one place, with a readiness score you can quote. The audit is done by an independent CPA firm for SOC 2 or an accredited certification body for ISO 27001, which the standards require.
You answer one questionnaire and NyxAssure drafts the full set. You edit and approve each one, every save is versioned, and approved policies go out for e-signature and to your staff.
We're in early access. Pre-book and we'll quote your exact scope. We promise the most competitive price on the market for industry-standard work.
Evidence, credentials and logs are encrypted and securely deleted within 30 days of the engagement ending. Your reports and dashboards stay available to your authorised users.